yag and pt_extbase extensions for TYPO3 allow remote attackers to bypass access restrictions
High severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Apr 14, 2025
Description
Published by the National Vulnerability Database
Oct 3, 2014
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Apr 14, 2025
Last updated
Apr 14, 2025
The Ajax dispatcher for Extbase in the Yet Another Gallery (yag) extension before 3.0.1 and Tools for Extbase development (pt_extbase) extension before 1.5.1 allows remote attackers to bypass access restrictions and execute arbitrary controller actions via unspecified vectors.
References